MEDIUM · 5.8

CVE-2021-1229

A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a slow system memory leak, which over time could lead to a denial...

Vulnerability Description

A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a slow system memory leak, which over time could lead to a denial of service (DoS) condition. This vulnerability is due to improper error handling when an IPv6-configured interface receives a specific type of ICMPv6 packet. An attacker could exploit this vulnerability by sending a sustained rate of crafted ICMPv6 packets to a local IPv6 address on a targeted device. A successful exploit could allow the attacker to cause a system memory leak in the ICMPv6 process on the device. As a result, the ICMPv6 process could run out of system memory and stop processing traffic. The device could then drop all ICMPv6 packets, causing traffic instability on the device. Restoring device functionality would require a device reboot.

CVSS Score

5.8

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
CiscoNx-Os5.2\(1\)sv5\(1.3a\)
CiscoNexus 1000 Virtual Edge For Vmware Vsphere-
CiscoNexus 1000V Switch For Microsoft Hyper-V-
CiscoNexus 1000V Switch For Vmware Vsphere-
CiscoMds 9148S-
CiscoMds 9250I-
CiscoMds 9706-
CiscoMds 9710-
CiscoNexus 3048-
CiscoNexus 31108Pv-V-
CiscoNexus 31108Tc-V-
CiscoNexus 31128Pq-
CiscoNexus 3132C-Z-
CiscoNexus 3132Q-V-
CiscoNexus 3132Q-X-
CiscoNexus 3132Q-Xl-
CiscoNexus 3164Q-
CiscoNexus 3172Pq-
CiscoNexus 3172Pq-Xl-
CiscoNexus 3232C-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-1229?

CVE-2021-1229 is a vulnerability with a CVSS score of 5.8 (MEDIUM). A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a slow system memory leak, which over time could lead to a denial...

How severe is CVE-2021-1229?

CVE-2021-1229 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-1229?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Nexus 1000 Virtual Edge For Vmware Vsphere, Cisco Nexus 1000V Switch For Microsoft Hyper-V, Cisco Nexus 1000V Switch For Vmware Vsphere, Cisco Mds 9148S.